NOTE:
If you delete a mobile node host by using the
no ip mobile host
command, all
security associations that you configured for this host are deleted.
•
To specify the mobile node, include the required
nai
keyword or the required
address
keyword, as follows:
•
To specify the network access identifier (NAI) for the mobile node, include the
nai
keyword. You must choose one of the following formats, where
user
represents the
user name and
realm
represents the domain name:
user@realm
,
@realm
, or
@
.
•
To specify a nonzero home address of the mobile node, include the
address
keyword
followed by the IP address of the mobile node.
•
To specify the security parameter index (SPI) value to authenticate inbound requests
and permit authentication for outbound registration requests, include the required
spi
keyword followed by a 4-octet hexadecimal number, in the range 0x100–0xFFFFFFFF.
•
To specify the authentication key for this security association, include the required
key
keyword followed by either the
hex
keyword or the
ascii
keyword, as follows:
•
To specify a hexadecimal key, use the
hex
keyword followed by a 32-character
(128-bit) hexadecimal value in the range 0x0–0xFFFFFFFE.
•
To specify an ASCII key, use the
ascii
keyword followed by an alphanumeric value
up to a maximum of 16 characters (128 bits).
•
To specify the number of seconds by which a registration request can exceed the time
value configured on the home agent, include the optional
replay timestamp within
keywords followed by the number of seconds, in the range 1–255; the default value is
7 seconds.
•
To specify the type of authentication algorithm for Mobile IP messages, include the
optional
algorithm
keyword followed by either the
hmac-md5
keyword or the
keyed-md5
keyword.
•
Examples
host1(config)#
ip mobile secure host 200.1.1.1 spi 0x398 key ascii w4ex algorithm
keyed-md5 replay timestamp within 225
or
host1(config)#
ip mobile secure host nai @amazon.net spi 0x100 key ascii pD4En
algorithm keyed-md5 replay timestamp within 100
•
Use the
no
version to delete the security associations for the specified host on the
virtual router.
•
See ip mobile secure host.
license mobile-ip home-agent
•
Use to configure the license key to enable a home agent.
•
Specify a name for the license key; up to a maximum of 16 alphanumeric characters.
Copyright © 2010, Juniper Networks, Inc.
312
JunosE 11.2.x IP Services Configuration Guide
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...